IT, Cloud & DevOps Blog

Ubuntu 14.04 — nova — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nova — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 April 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3449-1 Related CVEs: CVE-2015-3241 CVE-2015-3280 CVE-2015-5162 CVE-2015-7548 CVE-2015-7713 CVE-2015-8749 CVE-2016-2140 CVE-2014-3608  +9 more Upstream summary: George Shuklin discovered that OpenStack Nova incorrectly handled the migration process. A remote authenticated user […]

Read more
SLES 12 — libpng15 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpng15 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2690 CVE-2011-2692 CVE-2011-2691 CVE-2011-3328 CVE-2011-3464 Upstream summary: Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when […]

Read more
SLES 12 — libotr5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libotr5 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0706-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2851 Upstream summary: Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption […]

Read more
SLES 12 — libXfixes3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXfixes3 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1097-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1983 Upstream summary: Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — jakarta-taglibs-standard — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — jakarta-taglibs-standard — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1568-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-0254 Upstream summary: Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted […]

Read more
CHAT